← All terms

BrainHook Glossary

Penetration Testing

A simulated cyberattack on a computer system, network, or application to identify security vulnerabilities before malicious hackers can exploit them.

A controlled, authorized simulation of real-world cyberattacks conducted by security professionals to discover weaknesses in an organization's digital defenses. Testers use the same tools and techniques as malicious hackers—probing networks, applications, and systems—to identify exploitable vulnerabilities. Organizations then patch these gaps before actual attackers find them. Also called ethical hacking or white-hat hacking.

What this means in real life

A bank hires security experts to attempt breaking into its mobile app and internal servers; the testers discover a flaw allowing unauthorized access to customer accounts, which the bank fixes before launching publicly.

What it isn’t

Not a vulnerability scan that passively checks for known issues. True penetration testing actively exploits weaknesses to prove they're dangerous, mimicking how a real attacker would chain multiple flaws together to breach a system.

Commonly misused online

Tech influencers often conflate it with any security audit or compliance checklist. Actual penetration testing requires skilled professionals manually attempting to break in, not just running automated scanning tools and calling it 'pentesting.'